Windows 7 Forums Search
Welcome to Windows 7 Forums. Our forum is dedicated to helping you find solutions with any problems, errors or issues you are experiencing with Windows 7. The Windows 7 forum also covers news and updates and has an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.


Windows 7 - New trojan

 
11-09-2009   #1


Windows 7 Ultimate x64
 
 

New trojan

Hi, there's this new trojan which I found on a website.
Its filename is Bookmark.exe.
Strange is that only 22/40 anti malware engines were able to detect it.
Currently, I was trying Norton 360 beta 4 which has failed to detect it.
So far, this trojan has changed my IE8 homepage. Not sure what else it will do.

Here's the Virustotal link about the file analysis :
Virustotal. MD5: edc631287a36a3b91990ec4f90fd7dc2 Trojan.Pasta.dyq Generic.Malware.sp!.20613D67 Generic.Malware.sp!.20613D67


Edit: I ran a quick scan from Vipre AV and it has detected everything of this trojan.
Also, this trojan tried to execute itself and Vipre deteted it.
New trojan-capture.png


Last edited by Dinesh; 11-09-2009 at 02:42 PM.. Reason: added info
My System SpecsSystem Spec
11-09-2009   #2


Windows 7 Home Premium x32
 
 


Quote   Quote: Originally Posted by Dinesh View Post
Hi, there's this new trojan which I found on a website.
Its filename is Bookmark.exe.
Strange is that only 22/40 anti malware engines were able to detect it.
Currently, I was trying Norton 360 beta 4 which has failed to detect it.
So far, this trojan has changed my IE8 homepage. Not sure what else it will do.

Here's the Virustotal link about the file analysis :
Virustotal. MD5: edc631287a36a3b91990ec4f90fd7dc2 Trojan.Pasta.dyq Generic.Malware.sp!.20613D67 Generic.Malware.sp!.20613D67


Edit: I ran a quick scan from Vipre AV and it has detected everything of this trojan.
Also, this trojan tried to execute itself and Vipre deteted it.
Attachment 35882
Yes you see now why AV never reach 100% in detection of new malware - this is also what I was talking about in this post: The newest test: 0-Day Malware - 11/2009

BTW. score 22/40 isn't so bad, what if you catch virus which was created few hours/weeks ago with AV detection rate equal... 0/40 or 4/39... like in this example: Virustotal. MD5: 5a34fd85bdac65d50a56a2c69228a726 Packed.Generic.187 VirTool:Win32/Obfuscator.EF High Risk Fraudulent Security Program

Your protection should start from first very important layer:
1. Prevention
then... detection and then cure.
My System SpecsSystem Spec
11-09-2009   #3


Windows 7 Ultimate x64
 
 


Quote   Quote: Originally Posted by Creer View Post
Quote   Quote: Originally Posted by Dinesh View Post
Hi, there's this new trojan which I found on a website.
Its filename is Bookmark.exe.
Strange is that only 22/40 anti malware engines were able to detect it.
Currently, I was trying Norton 360 beta 4 which has failed to detect it.
So far, this trojan has changed my IE8 homepage. Not sure what else it will do.

Here's the Virustotal link about the file analysis :
Virustotal. MD5: edc631287a36a3b91990ec4f90fd7dc2 Trojan.Pasta.dyq Generic.Malware.sp!.20613D67 Generic.Malware.sp!.20613D67


Edit: I ran a quick scan from Vipre AV and it has detected everything of this trojan.
Also, this trojan tried to execute itself and Vipre deteted it.
Attachment 35882
Yes you see now why AV never reach 100% in detection of new malware - this is also what I was talking about in this post: The newest test: 0-Day Malware - 11/2009

BTW. score 22/40 isn't so bad, what if you catch virus which was created few hours/weeks ago with AV detection rate equal... 0/40 or 4/39... like in this example: Virustotal. MD5: 5a34fd85bdac65d50a56a2c69228a726 Packed.Generic.187 VirTool:Win32/Obfuscator.EF High Risk Fraudulent Security Program

Your protection should start from first very important layer:
1. Prevention
then... detection and then cure.
very well stated.
My System SpecsSystem Spec
.


11-09-2009   #4


W7 X-64 RTM,SUSE 11.1, XP PRO SP3 as a VM, VMware ESXi
 
 


Quote   Quote: Originally Posted by Dinesh View Post
Hi, there's this new trojan which I found on a website.
Its filename is Bookmark.exe.
Strange is that only 22/40 anti malware engines were able to detect it.
Currently, I was trying Norton 360 beta 4 which has failed to detect it.
So far, this trojan has changed my IE8 homepage. Not sure what else it will do.

Here's the Virustotal link about the file analysis :
Virustotal. MD5: edc631287a36a3b91990ec4f90fd7dc2 Trojan.Pasta.dyq Generic.Malware.sp!.20613D67 Generic.Malware.sp!.20613D67


Edit: I ran a quick scan from Vipre AV and it has detected everything of this trojan.
Also, this trojan tried to execute itself and Vipre deteted it.
Attachment 35882
Hi there
How about publishing the website so this can either be Blacklisted or checked with other programs (or both) or even better to see if one's own computer is resistant against the infection.

Publishing that trojan xxxx can or cannot be detected isn't of any use to man or beast unless you can give some indications as to where and how the infection arose.

Some of the analyses on the Security forum are just like asking the question "How long is a piece of String".

Cheers
jimbo
My System SpecsSystem Spec
11-09-2009   #5


Windows 7 Ultimate 64 Bit
 
 


Dinesh,

Have you tried detecting it with MSE?
My System SpecsSystem Spec
11-09-2009   #6


Windows 7 Ultimate x64 + x86 + Windows 8 x64
 
 


Jimbo, Dinesh,

I would prefer if this was not posted in the open - no problem to send it via a PM but things in the open could cause problems to less experienced users
My System SpecsSystem Spec
11-10-2009   #7


Windows 7 Ultimate x64
 
 


Quote   Quote: Originally Posted by Barman58 View Post
Jimbo, Dinesh,

I would prefer if this was not posted in the open - no problem to send it via a PM but things in the open could cause problems to less experienced users
I agree hence i didnt post the link in the forum.

@richfrogg:
I have tried scanning it with MSE and it didnt detect it.
My System SpecsSystem Spec
11-10-2009   #8


Windows 7 Ultimate x64 Service Pack 1 (Build 6.1.7601)
 
 


No Anti-Virus software out there is 100% full proof no matter what they say, its just to with sales.
Its just a endless cycle that will never end.
My System SpecsSystem Spec
11-10-2009   #9


Windows 7 Enterprise x64 SP1
 
 


Quote   Quote: Originally Posted by Barman58 View Post
Jimbo, Dinesh,

I would prefer if this was not posted in the open - no problem to send it via a PM but things in the open could cause problems to less experienced users

Just to make this completely clear - ANYBODY that posts a link to any form of Virus/malware will get an instant life ban on all our sites.

Where viruses etc are concerned we have a zero tolerance policy.
My System SpecsSystem Spec
11-10-2009   #10


Windows 7 Ultimate 32bit SP1
 
 


This has now been re-named to Trojan.StartPage.SSSPP ... This is a 'start page' hijacking.

URL's are changed all the time so this infection could be just about anywhere the site owner doesn't keep up with good surveillance and security.
My System SpecsSystem Spec
Reply

 New trojan problems?



Thread Tools



Similar Threads for: New trojan
Thread Forum
Trojan:Win32/FakeSpypro & Trojan:JS/FakeSpypro System Security
Solved Trojan, Please HELP!!! System Security
Trojan.VB.VZO System Security


All times are GMT -5. The time now is 01:29 AM.



Windows 7 Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows 7" and related materials are trademarks of Microsoft Corp.
© Designer Media Ltd
  

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30